OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100288

HIGH · CVSS 7.2 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Devolutions Server versions up to 2026.3.5.0 are vulnerable due to the cleartext storage of sensitive information in the database, allowing attackers with read access to extract external identity provider tokens and active session identifiers. This exposure can lead to unauthorized access to user accounts and systems. Organizations using affected versions should prioritize remediation to protect sensitive data and prevent potential breaches.

CVE
CVE-2026-100288
Severity
HIGH
CVSS
7.2
EPSS
0.07%

Original NVD Description

Cleartext storage of sensitive information in the database in Devolutions ServerĀ 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.